Security controls and deployment flexibility designed for enterprise use.
Platonic captures periodic screenshots and interaction metadata needed to reconstruct workflows, including clicks, scrolling, shortcuts, and application activity. It does not record typed text, clipboard contents, audio, camera input, or continuous video. Recording sessions remain visible to users and can be paused, reviewed, or deleted at any time.
Platonic follows a formal information security program covering access control, encryption, vulnerability management, monitoring, incident response, business continuity, vendor management, and employee security training. We are currently completing our SOC 2 compliance programs. For more detail, including policies, controls, subprocessors, and compliance status, visit our Trust Center.
Platonic acts as a data processor for employee data, processing it only on the customer’s instructions and under safeguards covering confidentiality, security, subprocessors, retention, and support for data subject rights. We are actively completing our GDPR compliance program. Beyond these requirements, Platonic includes additional privacy controls: users can pause and resume recording, exclude specific applications from capture, and choose which recordings they share.
Deployment is designed to be fast and flexible. Customers can use Platonic-managed infrastructure, deploy on infrastructure of their choice, or run fully on-premises; customer-managed and on-premises setups are typically lightweight and mainly require coordination with the customer’s IT team. End users then install a lightweight application from a secure link and can authenticate through credentials or SSO, with setup typically taking only minutes.
Customer data handling is designed to be flexible. Customers can choose where Platonic runs, where data is stored, and whether analysis is performed through external AI infrastructure or within their own environment. Access can be configured to match customer requirements, including setups where data remains entirely within customer-controlled infrastructure and is accessible only to authorized customer users.